NCHER 2018 Fall Legal Meeting October 5, 2018

Slides:



Advertisements
Similar presentations
Data Privacy and Security in the Cloud Presented by Robert J. Scott Managing Partner Scott & Scott, LLP
Advertisements

“Reaching across Arizona to provide comprehensive quality health care for those in need” Our first care is your health care Arizona Health Care Cost Containment.
NACARA Annual Conference Industry Perspectives Panel September 29,2014 Boise, Idaho Andy Madden Director State Government Affairs ACA International.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
IS BIG DATA GIVING YOU A BIG HEADACHE? Risk Reduction - Transactional, International and Liability Issues Oregon State Bar Corporate Counsel Section Fall.
© 2014 Nelson Brown Hamilton & Krekstein LLC. All Rights Reserved PRIVACY & DATA SECURITY: A LEGAL FRAMEWORK MOLLY LANG, PARTNER, NELSON BROWN & CO.
Visa Confidential1 Card Regulation; Pricing and Security Paul Russinoff State Government Relations.
3rd Party Solar PV Power Purchase Agreement (PPA)
3 rd -Party Solar PV Power Purchase Agreements (PPAs). / November At Least 24 States, + Washington DC and Puerto Rico,Authorize.
BIOTECH SUPPLY October 8-9, 2012 Crowne Plaza, Foster City, CA California Transparency in Supply Chain Act, SB 657, Chapter 556, Statutes of 2010 David.
© 2007 Morrison & Foerster LLP All Rights Reserved Privacy and Information Security Monthly Update January 9, 2007 Andrew Smith Tom Scanlon Joyita Basu.
COMPLYING WITH HIPAA BUSINESS ASSOCIATE REQUIREMENTS Quick, Cost Effective Solutions for HIPAA Compliance: Business Associate Agreements.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Payday Bar Association New Orleans – 11/5/09 Richard P. Eckman, Partner Presented by:
HIPAA PRIVACY AND SECURITY AWARENESS.
Policy Review (Top-Down Methodology) Lesson 7. Policies From the Peltier Text, p. 81 “The cornerstones of effective information security programs are.
Sharing Information With Affiliates and Third Parties F. Jay Meyer Vice President & Senior Counsel TD Bank, N.A. Portland, Maine.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
New Identity Theft Rules Rodney J. Petersen, J.D. Government Relations Officer Security Task Force Coordinator EDUCAUSE.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
3 rd Party Solar PV Power Purchase Agreement (PPA) / January 2016 At Least 26 States + Washington DC and Puerto Rico Authorize or Allow.
MARIJUANA LEGISLATION IMPLEMENTATION Introduction Amendment 64 -November 2012  Legalized the personal use and possession of marijuana for adults 21 years.
Final HIPAA-HITECH Rules, Cybersecurity, and Privacy Dino TsibourisMehmet Munur (614) (614)
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
CYBERSECURITY: RISK AND LIABILITY March 2, 2016 Joshua A. Mooney Co-chair-Cyber Law and Data Protection White and Williams LLP (215)
Key Points for a Privacy Programme for Multinationals Steve Coope.
NY DFS Cyber Regulation and the Impact on PA Mutual Insurers
3rd Party Solar PV Power Purchase Agreement (PPA)
The Pennsylvania State University
Student Lending Privacy and Data Security
GDPR (General Data Protection Regulation)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Coping With Regulatory Compliance Challenges
John L. Culhane, Jr., Partner
6 October 2016 Social media: do you have the right social media strategy that will impact your business’ growth? - Legal and Regulatory Issues William.
Microsoft 365 Get help with regulatory compliance
E&O Risk Management: Meeting the Challenge of Change
General Data Protection Regulation
General Data Protection Regulation
International Regulatory Trends
What Business Owners Need to Know About Data Privacy
The CFPB’s Legal Minefield for CREDIT UNIONS
The European Union General Data Protection Regulation (GDPR)
GDPR Security: How to do IT? IT reediness for competitive advantage
Cybersecurity for the Insurance Sector:
3rd Party Solar PV Power Purchase Agreement (PPA)
Bob Siegel President Privacy Ref, Inc.
Introduction to GDPR 09/11/2018.
Presented by Harry A. Strausser III Collections Industry Consultant
G.D.P.R General Data Protection Regulations
Current Privacy Issues That May Affect Your Credit Union
From DPA to GDPR: the key elements
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Tips on Privacy Audits and Assessments Insurance Consumer Affairs Exchange October 2, 2005 Kirk Herath, CPO & Associate General Counsel, Nationwide Insurance.
 GDPR Readiness Quiz Quick Insight: Quick Insight: Quick Insight:
ACI – 17th National Forum on Prepaid Card Compliance
General Date Protection Regulation
The General Data Protection Regulations 2016
General Data Protection Regulation (GDPR)
Recent Developments in Consumer Privacy
3rd Party Solar PV Power Purchase Agreement (PPA)
Data Privacy by Design Expanding Security for bepress Users
General Data Protection Regulation
Colorado “Protections For Consumer Data Privacy” Law
3rd Party Solar PV Power Purchase Agreement (PPA)
POST-ISSUANCE COMPLIANCE
Getting the Green Light on the Red Flags Rule
u.s. privacy law RICK JEFFRIES, CIPP/US
Privacy Update John L. Wood – Egerton, McAfee, Armistead & Davis, P.C.
and the New General Data Protection Regulation (GDPR) Requirements
Presentation transcript:

For Your Eyes Only: A Review of Developments in Cybersecurity and Data Privacy Law NCHER 2018 Fall Legal Meeting October 5, 2018 Hinshaw & Culbertson | Chicago, Illinois

Presentation Outline New York DFS Cybersecurity Rules EU General Data Protection Regulation California Consumer Privacy Act of 2018 Data Breach Notification Laws Enforcement Matters Reg. P Amendments

NY DFS Cybersecurity Rules Cybersecurity Rule, 23 NYCRR Part 500, applicable to “covered entities” Effective March 1, 2017, with various compliance deadlines September 3, 2018 – Sections 500.06 (audit trails), 500.08 (application security), 500.13 (limitation on data retention), 500.14(a) (regular monitoring) and 500.15 (encryption of nonpublic information) March 1, 2019 – Section 500.11 (third-party service provider security policy)

EU GDPR – Scope GDPR, effective May 25, 2018, applies to: “the processing of personal data of data subjects who are in the [EU] by a controller or processor not established in the [EU], where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the [EU]; or (b) the monitoring of their behaviour as far as their behaviour takes place within the [EU].” GDPR Art. 3.2.

EU GDPR – Requirements Consent Requirements Required Disclosures When Collecting Personal Data Right of Access Right to Rectification Right to Be Forgotten Right to Restriction of Processing Right to Data Portability Data Security Requirements Data Breach Procedures

CA Consumer Privacy Act Cal. Civ. Code §§ 1798.100 et seq. Enacted on June 28, 2018, effective January 1, 2020 S.B. 1121 CA AG regulations on or before January 1, 2020 CA AG cannot bring an enforcement action until the earlier of July 1, 2020 or 6 months after publication of the final regulations

CA Consumer Privacy Act Scope Applies to “businesses” that collect “personal information” regarding California residents Annual gross revenue in excess of $25m Exemptions Comply with federal, state, or local laws, or subject to GLBA

CA Consumer Privacy Act Requirements and Rights Right to know what personal information is being collected, whether personal information is sold or disclosed, and to whom Right to “opt-out” of sale of certain personal information Right “to be forgotten” Right to equal service and price

Data Breach Notification Laws State Law Developments Alabama Data Breach Notification Act of 2018, Ala. Code § 8-19F-1 Arizona, H.B. 2154 Colorado, H.B. 18-1128 Connecticut, S.B. 472 Oregon, S.B. 1551 South Dakota, S.D. Codified Laws, Chapter 22-40 (S.B. 62)

Data Breach Notification Laws Federal Developments Economic Growth, Regulatory Relief, and Consumer Protection Act (2018), Sec. 301 Treasury Dep’t Report, “A Financial System That Creates Economic Opportunities Nonbank Financials, Fintech, and Innovation” (July 2018) Consumer Information Notification Requirement Act (Rep. Luetkemeyer, H.R. 6743)

Enforcement Matters Federal Enforcement State Enforcement Actions LabMD, Inc. v. FTC (11th Cir. June. 6, 2018) State Enforcement Actions State of Pennsylvania v. Uber State of Washington v. Motel 6

Reg. P Amendments – Privacy Notices FAST Act of 2015 GLBA § 503(f) Financial institutions that meet certain conditions are not required to provide annual privacy notices to customers CFPB implementing regulations (Aug. 17, 2018) 83 Fed. Reg. 40945 Effective Sept. 17, 2018

Questions?

Contact Information Peter Cockrell Associate, Washington, DC McGlinchey Stafford (202) 802-9954 pcockrell@mcglinchey.com